Key points:
- Cyber Essentials Requirements are organised around five technical controls: firewalls, secure configuration, security update management, user access control, and malware protection.
- The requirements must be considered across the complete certification scope, including endpoints, Microsoft 365, business cloud services, internet-facing systems, and devices used for remote working.
- Under the current Cyber Essentials Requirements v3.3, cloud services that store or process organisational data cannot simply be excluded, and MFA must be used wherever the cloud service makes it available.
- FCA-regulated and audit-driven firms should prepare clear evidence of asset ownership, patching, access control, MFA, and device management before applying, even when completing the standard self-assessment.
- A structured Root.12 review can identify gaps across people, systems, and governance before they delay a Cyber Essentials or Cyber Essentials Plus assessment.
Cyber Essentials Requirements establish the minimum technical security controls that UK organisations should implement to reduce exposure to common internet-based attacks. The current requirements are set out in version 3.3, which applies to assessment accounts created from 27 April 2026. Although the certification process may appear straightforward, firms must understand how each requirement applies to their actual technology environment rather than answering solely from policies, assumptions, or supplier assurances.
This becomes more complex for regulated businesses that rely on Microsoft 365, cloud applications, remote employees, mobile devices, third-party administrators, and multiple endpoint types. Every system within scope must be assessed against the relevant controls, and responsibility for cloud security cannot be transferred entirely to the service provider. For FCA-regulated firms, this preparation can also support wider expectations around identifying vulnerabilities, assigning ownership, maintaining resilience, and demonstrating that remediation is being actively managed.
Many certification delays begin with differences between the organisation’s submitted answers and its live environment. Unsupported software may remain installed, MFA may not cover every cloud account, administrator privileges may be excessive, or remote devices may sit outside central management. Preparing accurate evidence before applying helps firms identify these weaknesses early and approach Cyber Essentials or CE+ with greater confidence. A Root.12 review strengthens this process by assessing the wider technology estate across 12 areas and connecting technical remediation with documented ownership, governance, and ongoing evidence.
The five Cyber Essentials Requirements regulated firms must meet
Cyber Essentials Requirements are built around five technical control areas intended to reduce exposure to common internet-based attacks. Each control must operate across the organisation’s defined certification scope, rather than existing only as a written policy or an informal responsibility assigned to an IT provider.
For regulated firms, the assessment should also establish clear ownership of each control. The organisation must understand which systems are protected, who is responsible for maintaining them, and how exceptions or security weaknesses are identified and resolved.
The five Cyber Essentials Requirements cover:
- Firewalls: Internet-connected devices and networks must be protected by appropriately configured firewalls. Default administrative passwords should be changed, unnecessary inbound connections should be blocked, and any permitted services should have a documented business need.
- Secure configuration: Computers, mobile devices, applications, cloud services, and network equipment should be configured to minimise unnecessary functionality. Unused accounts, default credentials, unneeded services, and software without a valid business purpose should be removed or disabled.
- Security update management: Operating systems, applications, firmware, browsers, and other software must remain supported and receive relevant security updates. Firms should be able to identify vulnerable software and demonstrate that remediation is managed consistently across the technology estate.
- User access control: Every user should have an individual account and only the permissions required for their role. Administrator access must be restricted, reviewed, and separated from routine activities such as email, document editing, and web browsing.
- Malware protection: Devices must use an appropriate method for preventing malicious software from running. Depending on the environment, this may include anti-malware software, application allow-listing, restricted application installation, or controls provided by a managed mobile platform.
These controls are closely connected. A securely configured laptop can still create risk if it is missing updates, while strong malware protection cannot compensate for an administrator account that is used for everyday work. The assessment therefore requires firms to consider how the controls operate together across their live environment, not as five isolated policy statements.

How Cyber Essentials Requirements apply to Microsoft 365, devices and remote working
Modern certification scopes extend beyond the traditional office network. The Cyber Essentials Requirements address cloud computing, home working, personally owned devices, and remote access because organisational data is now frequently processed outside a company’s physical premises.
Microsoft 365 is particularly important because it may provide email, document storage, collaboration, identity management, and administrative access to other business systems. Using a major cloud provider does not remove the applicant’s responsibilities. The provider protects the underlying service, while the firm remains responsible for areas such as user access, MFA, administrator roles, account management, and available security configurations.
Before applying, regulated firms should review:
- Microsoft 365 accounts: Active users, shared mailboxes, external accounts, administrator roles, dormant identities, and former employee access should all be reviewed.
- Multi-Factor Authentication: MFA should be applied consistently to relevant cloud accounts, with particular attention given to administrative and privileged users.
- Corporate devices: Laptops, desktops, mobile phones, and tablets that access company data should follow consistent configuration, update, access, and malware-protection policies.
- Personally owned devices: Personal devices used to access work email, documents, or cloud applications may fall within the certification scope and cannot be ignored simply because the company does not own them.
- Remote working: Devices used by home workers remain relevant to the assessment. Although a home internet router may not always be included, the device itself still requires an appropriately configured software firewall and other applicable controls.
- Cloud and SaaS systems: Microsoft 365, cloud applications, virtual desktops, mobile-device management platforms, and other subscribed services that hold or process organisational data should be identified and assessed.
- Third-party access: Accounts used by contractors, outsourced IT providers, or external administrators should be included in access reviews and protected according to the same security principles as internal accounts.
IASME guidance states that devices accessing organisational data or services are within scope, including devices used by home workers and relevant personal mobile phones. It also identifies services such as Microsoft 365, cloud applications, virtual desktops, and mobile-device management systems as part of the environment organisations must consider.
TIP: Build the certification scope from actual access records, device inventories, and cloud subscriptions. Relying only on a list of company-owned hardware can leave Microsoft 365 accounts, personal devices, remote users, and third-party access outside the readiness review.
How regulated firms should evidence Cyber Essentials Requirements before applying
Cyber Essentials is a verified self-assessment, but regulated firms should approach it as an evidence-based review rather than a questionnaire completed from memory. The NCSC provides both the technical requirements and a preview of the assessment questions so organisations can identify gaps before opening the formal application. The submitted answers must also be approved by a board member or equivalent, increasing the importance of ensuring that every declaration accurately reflects the live environment.
Evidence preparation is particularly valuable for businesses operating under regulatory, insurer, investor, or client scrutiny. Cyber Essentials does not require firms to upload a complete governance library during the standard assessment, but organised records allow the person completing the application to validate scope, confirm technical settings, and resolve inconsistencies with the IT provider before submission.
| Cyber Essentials area | Evidence to prepare | What the evidence should confirm |
| Certification scope | Network diagrams, cloud-service lists and business-unit records | Which users, devices, locations and services are included |
| Hardware and devices | Current inventories of laptops, desktops, servers, mobiles and network equipment | That all devices accessing organisational data have been identified |
| Software and patching | Software inventories, support-status records and update reports | That software remains supported and relevant security updates are applied |
| Microsoft 365 and cloud systems | Tenant settings, MFA reports, role assignments and account lists | That cloud identities and privileged access are appropriately protected |
| User access control | Joiner, mover and leaver records, access reviews and administrator lists | That access is assigned according to business need and removed when no longer required |
| Firewalls and remote access | Firewall rules, router configurations, VPN settings and exposed-service records | That inbound access is restricted and every exception has a legitimate purpose |
| Malware protection | Endpoint-security dashboards, device-compliance reports and application-control settings | That malware controls are active and consistently deployed across the scope |
Evidence should be recent enough to describe the environment being certified. A spreadsheet created during the previous year may not account for new cloud applications, recently issued laptops, contractors, or changes to administrative access. For firms preparing for Cyber Essentials Plus, these records also help reduce differences between the self-assessment scope and the systems later selected for technical testing.
Common Cyber Essentials gaps that cause assessment delays
Delays usually occur when a firm’s written answers describe the intended security position but do not match its current devices, accounts, software, or cloud configuration. This is especially common in growing businesses where technology has been introduced by different teams and suppliers without one complete view of the environment.
Remote working also increases the likelihood of missed assets. IASME states that devices used by home workers to access organisational data or services are within scope, including relevant personal mobile phones. Cloud services such as Microsoft 365, virtual desktops and device-management platforms must also be considered, with the applicant ultimately responsible for ensuring the applicable controls are implemented.
Common gaps that can delay Cyber Essentials or CE+ include:
- Unsupported operating systems, applications, mobile devices or network equipment
- Missing or inconsistent security-update reporting
- Personal and remote-working devices excluded from the asset inventory
- Microsoft 365 accounts without the required MFA protection
- Excessive administrator permissions or privileged accounts used for everyday work
- Dormant accounts belonging to former employees or contractors
- Cloud applications introduced without security or access reviews
- Firewall rules that permit unnecessary inbound connections
- Inconsistent malware protection across laptops and mobile devices
- Certification answers provided by different teams without a final technical validation
- Differences between the Cyber Essentials scope and the environment presented for CE+ testing
Support Tree offers a first-attempt pass guarantee for Cyber Essentials and Cyber Essentials Plus and maintains a 100% CE/CE+ pass rate. Root.12 helps identify these gaps before the assessment begins, giving firms time to remediate issues and validate their environment before submission or technical testing.
These gaps are not always complex to remediate, but they become disruptive when discovered after the application has started. The strongest preparation process assigns an owner to every issue, records the required corrective action, and verifies the live configuration before the final answers are approved.
TIP: Ask the person responsible for each control to validate the supporting evidence, not only the questionnaire response. A policy owner may confirm that MFA is required, while a Microsoft 365 report may reveal accounts where it is not actually enforced.

How to prepare Cyber Essentials Requirements for the CE+ technical audit
Cyber Essentials Plus assesses the same five control areas as standard Cyber Essentials, but adds independent technical testing to verify that the declared controls work in practice. The scope of the CE+ audit must match the scope of the associated Cyber Essentials assessment, so devices, users, cloud services, and organisational boundaries should be agreed before the initial questionnaire is submitted.
This creates a higher evidence requirement for firms progressing to CE+. An answer that appears acceptable in the self-assessment may create problems when an assessor tests representative devices or compares the declared scope with the live environment. Businesses should therefore complete technical validation before arranging the audit rather than using the assessment to discover configuration gaps.
Preparation for Cyber Essentials Plus should include:
- Confirming that the CE+ scope matches the existing Cyber Essentials certificate
- Checking representative Windows, macOS, mobile, and remote-working devices
- Verifying that supported software and operating systems are fully updated
- Reviewing internet-facing services and external vulnerability exposure
- Confirming that malware protection is active and reporting correctly
- Testing whether users can download or execute potentially harmful files
- Verifying MFA and access controls across Microsoft 365 and other cloud platforms
- Ensuring administrator accounts are separated from routine user activity
- Checking that device-management policies apply to all relevant endpoints
- Resolving failed updates, inactive security agents, and configuration exceptions
- Preparing technical contacts and suitable devices for the assessor to test
Cyber Essentials Plus must follow a successful Cyber Essentials assessment, and the technical audit normally needs to be completed within three months of the basic certification. Firms should plan remediation and assessor availability before this period begins, particularly where multiple offices, cloud environments, or remote device groups are included.
A successful self-assessment should therefore be viewed as the start of CE+ preparation rather than proof that the environment will automatically pass technical testing. The more accurately the original answers reflect the live estate, the lower the risk of delays when controls are independently verified.
How a Root.12 review supports Cyber Essentials Requirements
A Cyber Essentials readiness review should do more than compare questionnaire answers with written policies. Regulated firms need a structured way to discover assets, verify technical settings, assign remediation responsibilities, and retain evidence that remains useful after certification.
Root.12 maps the organisation’s technology estate across 12 assessment areas covering security, operations, assurance, and growth. It creates a scored baseline and an evidence library that can help firms identify weaknesses before entering the Cyber Essentials or CE+ process.
A Root.12 review can help businesses:
- Define the certification scope across users, devices, locations, and cloud services
- Review Microsoft 365 identity, MFA, and administrator configurations
- Identify unsupported devices, applications, and operating systems
- Check patching performance and unresolved security vulnerabilities
- Assess endpoint protection and device-management coverage
- Review joiner, mover, and leaver access processes
- Detect dormant, shared, or excessively privileged accounts
- Document firewall, remote-access, and internet-facing service configurations
- Assign owners and deadlines to remediation actions
- Create structured evidence for the Cyber Essentials questionnaire
- Prepare the same environment for subsequent CE+ technical testing
- Maintain visibility after certification rather than rebuilding evidence annually
This wider review is particularly useful for FCA-regulated and audit-driven firms because Cyber Essentials is rarely their only assurance requirement. The same evidence may later support client due diligence, cyber insurance reviews, operational resilience assessments, and broader governance reporting. Support Tree positions Root.12 as a continuously maintained framework rather than a one-off preparation exercise, helping organisations connect certification controls with longer-term security ownership.
TIP: Complete the Root.12 gap review before purchasing or opening the formal assessment. This gives the business time to remediate unsupported software, inconsistent MFA, unmanaged devices, and access-control weaknesses without working against a certification deadline.

Why preparing Cyber Essentials Requirements early reduces certification risk
Meeting Cyber Essentials Requirements is not simply a matter of completing a questionnaire. Regulated UK firms must understand how the five control areas operate across Microsoft 365, cloud systems, corporate devices, remote workers, privileged accounts, and third-party access. The application is strongest when every response reflects the live environment and can be supported by current technical evidence.
For FCA-regulated and audit-driven organisations, early preparation also improves more than the certification outcome. Accurate asset records, consistent MFA, effective patching, controlled administrator access, and managed endpoints all support wider governance, insurer scrutiny, client due diligence, and operational resilience expectations. These controls should therefore be maintained as ongoing business processes rather than introduced only when an assessment deadline approaches.
The firms most likely to avoid delays are those that define their scope early, identify ownership for each requirement, review Microsoft 365 and endpoint configurations, and remediate unsupported software or access weaknesses before submission. This is particularly important for organisations planning to progress from Cyber Essentials to Cyber Essentials Plus, where technical testing may expose any difference between the questionnaire and the actual environment.
A structured Root.12 review helps bring this preparation into one controlled process. By identifying security gaps, prioritising remediation, assigning responsibility, and organising evidence before the Cyber Essentials or CE+ assessment begins, regulated firms can approach certification with greater confidence and maintain a stronger, more defensible security position after the certificate has been awarded.
Planning for Cyber Essentials or CE+? Start with a structured readiness review to identify control gaps, organise evidence and prepare your environment before assessment with Support Tree’s Cyber Essentials support and Root.12 Framework.
FAQ:
Cyber Essentials requirements cover five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. Regulated UK firms must apply these controls consistently across the systems within their certification scope, including devices, cloud services, user accounts and relevant business applications.
Cyber Essentials requirements apply to Microsoft 365 where the platform is used to access, store or process organisational data. Firms should review MFA, administrator privileges, dormant accounts, user access and security configurations to ensure Microsoft 365 controls accurately reflect the answers provided during certification.
Remote-working and personally owned devices may fall within the Cyber Essentials scope when they access organisational data or services. Firms should identify these devices, confirm appropriate firewall, update, access and malware controls, and ensure they are included in asset and device-management processes before submitting the assessment.
FCA-regulated firms should prepare current asset inventories, software and patching records, MFA reports, administrator and user-access records, device-management information, firewall configurations and evidence of remediation. This helps ensure the Cyber Essentials assessment reflects the live environment and reduces inconsistencies during certification or subsequent CE+ testing.
Firms preparing for Cyber Essentials Plus should first confirm that the certification scope matches their Cyber Essentials assessment, then validate patching, MFA, endpoint protection, administrator access, device management and internet-facing systems. Support Tree’s Root.12 process helps identify and remediate gaps before testing and supports its first-attempt CE/CE+ pass guarantee.